Anonymous password-based key exchange with low resources consumption and better user-friendliness

Research output: Contribution to journalArticlepeer-review

12 Scopus citations

Abstract

Anonymous password authenticated key exchange (APAKE) protocols allow the server to authenticate its clients without revealing their identities. In this paper, we first construct a basic protocol SAPAKE by using the homomorphic encryption scheme and an auxiliary memory device. Compared with the previous ones, SAPAKE is more suitable for those privacy-sensitive applications (e.g., cloud computing) where reducing server payload and improving user experience are both essential. Furthermore, we refine SAPAKE by removing the use of the memory device to gain an enhanced extension SAPAKE+ without increasing the resources consumption. SAPAKE+ achieves better user-friendliness than SAPAKE while it requires publishing more public parameters. Both of our protocols are practical due to their low (computation and communication) resources consumption and better user-friendliness, and achieve provable security in the random oracle model.

Original languageEnglish
Pages (from-to)1379-1393
Number of pages15
JournalSecurity and Communication Networks
Volume5
Issue number12
DOIs
StatePublished - Dec 2012

Keywords

  • Authentication
  • Client anonymity
  • Key exchange
  • Password
  • Provable security
  • Smart card

Fingerprint

Dive into the research topics of 'Anonymous password-based key exchange with low resources consumption and better user-friendliness'. Together they form a unique fingerprint.

Cite this